Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-42361
Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoin…
Hertzbeat
1.6.0+
CRITICAL 9.8
CVE-2024-43202
Exposure of Remote Code Execution in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
We recommend users to upgr…
Dolphinscheduler
3.2.2+
CRITICAL 9.8
CVE-2024-38856 KEVEPSS 99%
Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to versi…
Ofbiz
18.12.15+
CRITICAL 9.8
CVE-2024-42447
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.
This issue affects Apache Airflow Providers FAB: 1.2.1 (when used wit…
Apache Airflow Providers Fab
Patch available
CRITICAL 9.8
CVE-2024-36268
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.10.0 through 1.12…
Inlong
1.13.0+
CRITICAL 9.1
CVE-2023-48396
Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge
any token to log in an…
Seatunnel
Mitigation only
CRITICAL 9.1
CVE-2024-29070
On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …
Streampark
2.1.4+
CRITICAL 9.1
CVE-2024-29736
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style att…
Cxf
3.5.9 / 3.6.4+
CRITICAL 9.8
CVE-2024-39887
An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certa…
Superset
4.0.2+
CRITICAL 9.8
CVE-2024-36522
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…
Wicket
8.16.0 / 9.18.0+
CRITICAL 9.8
CVE-2024-39864
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integratio…
Cloudstack
4.18.2.1 / 4.19.0.2+
CRITICAL 9.8
CVE-2024-38346
The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and …
Cloudstack
4.18.2.1 / 4.19.0.2+
CRITICAL 9.8
CVE-2024-38474
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by th…
HTTP Server
2.4.60+
CRITICAL 9.8
CVE-2024-38476EPSS 42%
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend a…
HTTP Server
2.4.60+
CRITICAL 9.1
CVE-2024-38475 KEVEPSS 100%
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are p…
HTTP Server
2.4.60 / 10.2.1.14-75sv+
CRITICAL 9.1
CVE-2024-29868EPSS 6%
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery …
Streampipes
after 0.93.0
CRITICAL 9.8
CVE-2024-36265
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.
This issue affects Apache Submarine Server Co…
Submarine
Mitigation only
CRITICAL 9.8
CVE-2024-36264
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils.
If the user doesn't explicitly set `submari…
Submarine
Patch available
CRITICAL 9.1
CVE-2024-36104EPSS 87%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…
Ofbiz
18.12.14+
CRITICAL 9.1
CVE-2024-34365
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave.
A…
Karaf Cave
Mitigation only
CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …
Ofbiz
18.12.13+
CRITICAL 9.8
CVE-2024-26579
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,
the attackers can by…
Inlong
1.12.0+
CRITICAL 9.8
CVE-2024-27348 KEVEPSS 99%
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & …
Hugegraph
1.3.0+
CRITICAL 9.1
CVE-2024-27349
Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0.
User…
Hugegraph
1.3.0+
CRITICAL 9.8
CVE-2024-31864
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin.
The attacker can inject sensitive configuration or malic…
Zeppelin
0.11.1+
CRITICAL 9.8
CVE-2024-31866
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin.
The attackers can execute shell scripts or malicious code by overriding co…
Zeppelin
0.11.1+
CRITICAL 9.8
CVE-2024-29006
By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead t…
Cloudstack
4.18.1.1+
CRITICAL 9.8
CVE-2024-23538
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…
Fineract
1.9.0+
CRITICAL 9.8
CVE-2024-23539
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Finer…
Fineract
1.9.0+
CRITICAL 9.8
CVE-2024-27438
Download of Code Without Integrity Check vulnerability in Apache Doris.
The jdbc driver files used for JDBC catalog is not checked and may resulting …
Doris
2.0.5+